Knowledge isolation method based on organizational structure and user responsibilities
By constructing a multi-dimensional knowledge isolation method based on organizational structure and user responsibilities, the problems of rigid permissions and single isolation dimensions in enterprise internal knowledge management are solved, achieving efficient and secure knowledge access control, adapting to complex business changes and providing full lifecycle security auditing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-24
- Publication Date
- 2026-03-27
AI Technical Summary
Existing technologies in enterprise knowledge management suffer from rigid permission models that are difficult to adapt to complex and ever-changing organizational structures and dynamic task groupings. They also have a single isolation dimension, lack multi-dimensional unified control capabilities, and have vague security boundaries, making it impossible to effectively prevent the leakage of sensitive information.
A multi-dimensional knowledge isolation approach based on organizational structure and user responsibilities is adopted. Through an isolation dimension management center, a multi-dimensional knowledge isolation method module, and a knowledge production center, a multi-dimensional knowledge isolation system is constructed. Combined with isolation strategies based on organization, task, identity, and level, dynamic access control is achieved.
It achieves a dynamic balance between security and efficiency, improves the granularity of knowledge isolation and the adaptability of access control, supports unified access governance in complex scenarios, ensures that knowledge assets circulate within a strictly authorized scope, and prevents unauthorized access and information leakage.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer information security and access control technology, specifically to a knowledge isolation method based on organizational structure and user responsibilities. Background Technology
[0002] With the rapid development of artificial intelligence technology, the role of large-scale pre-trained models in enterprise knowledge management and intelligent applications is becoming increasingly prominent. Building an internal AI knowledge base can effectively integrate scattered knowledge resources within an organization, improving the efficiency of information retrieval and decision support. However, in the process of integrating internal knowledge assets into large models for training or inference, ensuring the security and controllability of knowledge, and preventing the leakage or unauthorized misuse of sensitive information, has become a core challenge for enterprises. Traditional knowledge management or access control systems typically employ a single permission model, which suffers from insufficient flexibility and difficulty in dynamic adjustment when dealing with complex and ever-changing organizational structures, temporary task collaborations, and fine-grained knowledge isolation requirements.
[0003] To address the aforementioned knowledge security access control issues, existing technologies have proposed various improvement schemes. Some schemes attempt to integrate organizational hierarchies into the permission system, using predefined static organizational nodes such as departments and teams to delineate data access boundaries. These schemes, by establishing the affiliation between users and organizational units, restrict users to accessing knowledge assets only within their own organizational scope, achieving a certain degree of vertical knowledge isolation. However, their permission models rely too heavily on stable organizational structures and cannot adapt to dynamic collaboration scenarios such as temporary cross-departmental project team formations. When employees participate in multiple task groups simultaneously, the issues of permission overlap and conflicts are difficult to resolve properly. Other schemes focus on the fine-grained design of user identities and roles, defining more granular operational permission roles and authorizing based on user job titles and positions. These schemes improve the accuracy of permission allocation, but the complexity of maintaining roles and permissions increases dramatically with business changes, and they lack the ability to perform multi-dimensional security classification of knowledge assets themselves, failing to implement mandatory access control based on information security levels, thus falling short in addressing high-security knowledge protection requirements.
[0004] In summary, existing technologies have the following shortcomings in implementing enterprise internal knowledge bases, especially in providing a secure corpus foundation for large AI models: First, the permission model is rigid, making it difficult to adapt to both long-term stable organizational structures and short-term dynamic task groupings; second, the isolation dimension is singular, lacking the ability to uniformly manage and comprehensively judge multiple dimensions such as organization, task, identity, and level; third, the security boundaries are vague, failing to build a hierarchical and scalable protection system for knowledge of different security levels. Therefore, there is an urgent need for a knowledge isolation method that can deeply integrate organizational structure and user responsibilities, support multi-dimensional flexible strategies, and dynamically adapt to business changes, thereby building a solid security foundation for internal AI knowledge bases, ensuring efficient use of knowledge while preventing unauthorized access and information leakage risks, and achieving a balance between security and efficiency. Summary of the Invention
[0005] To address these issues, this invention provides a knowledge isolation method based on organizational structure and user responsibilities.
[0006] This invention is achieved through the following technical solution: a knowledge isolation method based on organizational structure and user responsibilities, consisting of three core modules: an isolation dimension management center (1), a multi-dimensional knowledge isolation method module (2), and a knowledge production center (3), to realize secure access control of the internal AI knowledge base and prevent knowledge from being abused. The method is characterized in that: the isolation dimension management center (1) is connected to the multi-dimensional knowledge isolation method module (2) through a dimension configuration channel (4) to transmit isolation dimension strategies of organization, task, identity, and level; the multi-dimensional knowledge isolation method module (2) is connected to the knowledge production center (3) through an isolation execution channel (5) to implement isolation control on knowledge access requests according to the received dimension strategies; and the knowledge production center (3) outputs knowledge content that conforms to the isolation strategy to authorized users through a knowledge output channel (6).
[0007] The isolation dimension management center (1) as described in claim 1 is responsible for designing and managing the core dimensions of knowledge isolation, characterized in that: it includes an organizational framework management unit (7) and a task grouping management unit (8), wherein the organizational framework management unit (7) is directly connected to the task grouping management unit (8); the organizational framework management unit (7) is used to maintain long-term isolation dimensions based on a stable organizational structure; the task grouping management unit (8) is used to maintain penetrating isolation dimensions based on temporary and dynamically adjusted tasks; the isolation dimension management center (1) also includes a level management unit (9) and a role permission management unit (10), wherein the level management unit (9) is directly connected to the role permission management unit (10) and is connected to the multidimensional knowledge isolation module (2) through a dimension configuration channel (4).
[0008] The multidimensional knowledge isolation method module (2) as described in claim 1 is responsible for performing knowledge access isolation based on multiple dimensions, characterized in that: it includes an organization-based isolation method unit (11), a task-based isolation method unit (12), an identity-based isolation method unit (13), and a level-based isolation method unit (14); the organization-based isolation method unit (11), the task-based isolation method unit (12), the identity-based isolation method unit (13), and the level-based isolation method unit (14) are set in parallel and connected to the knowledge production center (3) through the isolation execution channel (5).
[0009] The knowledge production center (3) as described in claim 1 is responsible for the production and output of knowledge under the control of the isolation strategy, characterized in that: it includes a knowledge storage unit (15) and an access control unit (16), wherein the knowledge storage unit (15) is directly connected to the access control unit (16); the access control unit (16) outputs knowledge content to an external user interface through a knowledge output channel (6).
[0010] The organizational framework unit (7) as described in claim 2 is responsible for maintaining a stable organizational structure isolation dimension, characterized in that: it receives organizational structure configuration information through the dimension configuration channel (4) and outputs organizational isolation strategy to the multidimensional knowledge isolation method module (2).
[0011] The task grouping unit (8) as described in claim 2 is responsible for maintaining the dynamic task grouping isolation dimension, characterized in that: it receives dynamic adjustment information of task grouping through the dimension configuration channel (4) and outputs the task isolation strategy to the multidimensional knowledge isolation method module (2).
[0012] The isolation dimension management center (1) as described in claim 2 further includes a level management unit (9) and a role permission unit (10), wherein the level management unit (9) is directly connected to the role permission unit (10); the level management unit (9) outputs a level isolation strategy to the multidimensional knowledge isolation method module (2) through the dimension configuration channel (4); and the role permission unit (10) outputs an identity (role) isolation strategy to the multidimensional knowledge isolation method module (2) through the dimension configuration channel (4).
[0013] The organization-based isolation method unit (11) as described in claim 3 is responsible for implementing knowledge isolation according to the organizational structure, characterized in that: it receives access requests through the isolation execution channel (5) and determines whether access to the knowledge production center (3) is allowed according to the organizational isolation strategy.
[0014] The task-based isolation method unit (12) as described in claim 3 is responsible for implementing knowledge isolation according to task grouping, characterized in that: it receives access requests through the isolation execution channel (5) and determines whether access to the knowledge production center (3) is allowed according to the task isolation strategy.
[0015] The identity-based isolation method unit (13) as described in claim 3 is responsible for implementing knowledge isolation based on user role permissions, characterized in that: it receives access requests through the isolation execution channel (5) and determines whether access to the knowledge production center (3) is allowed based on the identity (role) isolation strategy.
[0016] Compared with traditional knowledge access control methods, the advantages of this invention are: 1. Achieving a dynamic balance between security and efficiency, reducing knowledge management security risks. Traditional access control models are typically based on static, single organizational structures or roles for permission division, making it difficult to adapt to the frequent cross-departmental collaborations and dynamic task grouping needs in modern enterprises. This invention introduces a stable "organizational framework" and a dynamic "task grouping" dual dimension, integrating "level" and "role permissions" to construct a multi-dimensional knowledge isolation system. This allows the system to build a basic security boundary based on a long-term stable organizational structure, while flexibly responding to temporary, pervasive project task needs. Under the premise of ensuring the security of core knowledge assets (building a "high wall within a small courtyard"), it supports the efficient flow and collaborative utilization of knowledge within the authorized scope, fundamentally reducing the operational inconvenience or security strategy evasion risks caused by rigid permission models. 2. Enhance the granularity and intelligence of knowledge isolation. Traditional role- or organization-based isolation methods are coarse-grained and cannot precisely control the security attributes of the knowledge content itself. The multi-dimensional knowledge isolation method proposed in this invention comprehensively utilizes isolation strategies based on organization, task, identity, and level to achieve finer-grained access control. The system can perform real-time, dynamic, and comprehensive permission determination based on the security level of the knowledge asset, the user's organizational unit, the tasks they participate in, and their personal role responsibilities. This provides a solid security foundation for building an internal AI knowledge base, ensuring that the corpus provided for training or inference of large models is within a strictly authorized scope, effectively preventing the unauthorized leakage and misuse of highly sensitive or high-value knowledge. 3. Enhance the adaptability and scalability of the access control system. Traditional solutions often require extensive manual reconfiguration of access control systems when organizational structures are adjusted or business scope expands, resulting in high maintenance costs and a high risk of errors. This invention establishes an "isolation dimension management center" to centrally and uniformly manage core dimensions such as organization, tasks, levels, and roles, enabling each dimension to be maintained independently and flexibly combined. When new business departments are added, temporary projects are launched, or security levels are adjusted, administrators can quickly configure corresponding policies through the management center. The system can automatically synchronize the new policies to the "knowledge isolation method" execution layer, achieving immediate and accurate control over new knowledge assets and user access permissions. This design significantly improves the system's adaptability to business changes and supports the smooth expansion of the access control model as the complexity of the enterprise increases. 4. Supports unified access control and auditing in complex scenarios. Within large organizations, employees often belong to multiple permanent departments and participate in multiple temporary projects simultaneously. Traditional methods easily lead to overlapping and conflicting permissions, and auditing is difficult. This invention, through the linkage of a "knowledge production center" and a multi-dimensional isolation method, places all knowledge generation, storage, and access behaviors under a unified access control framework. The system can clearly record the specific organization, task, identity, level, and other multi-dimensional policies upon which each knowledge access request is based, providing complete and traceable security audit logs. This not only facilitates global access control and compliance checks for administrators but also provides data support for continuous optimization of security policies, achieving controllable, manageable, and traceable knowledge throughout its entire lifecycle. 5. Building a Trusted and Secure Foundation for AI-Driven Knowledge Applications. When using internal knowledge bases to train or serve large models, the security of the corpus is paramount. This invention establishes a full-chain isolation mechanism from knowledge production to access control, ensuring that only knowledge that has undergone rigorous multi-level authorization screening can enter specific AI application processes. This mechanism removes obstacles to the secure and compliant use of large models within enterprises, enabling them to confidently leverage their own knowledge assets to empower advanced applications such as intelligent question answering and decision support. While fully utilizing AI's effectiveness, it also strengthens data security defenses and promotes a secure and trustworthy intelligent transformation. Attached Figure Description
[0017] Figure 1 A detailed description of the implementation process for the isolation dimension management center. Figure 2 A detailed description of the implementation process for the knowledge isolation method. Figure 3 Process description for the specific implementation of the knowledge production center Detailed Implementation
[0018] The specific embodiments of the present invention will now be described clearly and in detail with reference to the accompanying drawings. The described embodiments are merely a part of the embodiments of the present invention.
[0019] The technical solution of this invention to solve the above-mentioned technical problems is: a knowledge isolation method based on organizational structure and user responsibilities. This invention includes: an isolation dimension management center, a multi-dimensional knowledge isolation method, and a knowledge production center.
[0020] I) Isolation Dimension Management Center The Isolation Dimension Management Center is the central management hub of the entire methodology, responsible for the unified definition, configuration, and maintenance of the core dimensions that constitute the knowledge isolation strategy. The specific implementation steps are as follows: 1. Dimension Definition and Modeling: Establish and maintain data models and strategy libraries for four core isolation dimensions; Organizational Framework Dimension: This dimension involves recording and maintaining the company's static organizational structure information, including the hierarchical relationships, affiliations, and unique identifiers of permanent units such as departments, business units, and offices. This dimension experiences low data change frequency, serving as a foundation for stability. Task grouping dimension: Supports the creation and management of dynamic, cross-organizational temporary task groups or project groups. Administrators can specify task group names, objectives, cycles, members, and task group-specific knowledge access policies. This dimension supports organizational penetration, adapting to business dynamics; Security Level Dimension: Define the security level system for knowledge assets and clarify the confidentiality requirements, access control strength, and approval process for each level; Role-based access control: Define standard operation roles in the system and bind a set of fine-grained operation permissions to each role.
[0021] 2. Dimension Association and Policy Configuration: Supports associating users with multiple dimension instances simultaneously. For example, a user may belong to a specific department, participate in a research and development project team, and possess the corresponding security level. The management center allows administrators to configure access control policies for specific knowledge directories or knowledge items, consisting of combinations of one or more of the aforementioned dimensions.
[0022] 3. Policy Deployment and Synchronization: The configured multidimensional isolation policy is synchronized to the multidimensional knowledge isolation method execution engine in real time to ensure that the access control rules take effect immediately.
[0023] (ii) Multidimensional knowledge isolation method The multidimensional knowledge isolation method is the policy execution engine, responsible for making real-time, dynamic access control decisions based on the policies provided by the isolation dimension management center when a user initiates a knowledge access request. The specific workflow is as follows: 1. Access Request Interception and Parsing: When a user attempts to access a specific knowledge asset in the knowledge production center through the system interface, the request is intercepted, and the request subject, request object, and request operation (such as read or modify) are parsed out.
[0024] 2. Multi-dimensional context acquisition: Based on the request subject, the system retrieves all the current dimensional contexts of the user from the isolated dimensional management center in real time, including the static organizational unit to which the user belongs, the dynamic task group to which the user participates, the set of roles granted to the user, and the user's security level.
[0025] 3. Policy Matching and Decision: Based on the requested object, retrieve the multi-dimensional access control policy applicable to the knowledge asset. Match and logically calculate the user's multi-dimensional context with the dimensional conditions specified in the policy; Based on organizational isolation: Check whether the user's organization is within the scope of organizations that are allowed to access the knowledge assets; Based on task isolation: Check whether the task group currently participated in by the user is authorized to access the knowledge asset; Based on identity isolation: Check whether the role granted to the user contains the permissions required to perform the currently requested operation; Based on security level isolation: check whether the user's security level is not lower than the security level of the knowledge asset, and whether the operation complies with the rules for flow between security levels; The above isolation measures work together to ultimately produce an access control decision of "allow," "deny," or "requires additional approval."
[0026] 4. Decision Execution and Log Recording: Execute access control decisions. If allowed, open the access channel; if denied, return a permission denied message. Regardless of the outcome, record the access request, the user's multidimensional context, the matching policy, the decision result, and the timestamp in the security audit log.
[0027] (iii) Knowledge Production Center The knowledge production center is a core storage and processing platform that carries and manages an enterprise's knowledge assets throughout their entire lifecycle, and it is deeply integrated with multi-dimensional knowledge isolation methods. The specific implementation method is as follows: 1. Knowledge Asset Storage and Labeling: When new knowledge assets are created or imported, the knowledge production center requires the creator or administrator to label them with necessary multi-dimensional attributes, including at least: the knowledge category to which they belong, the associated organizational framework, the associated task grouping, and the security level of the knowledge. These attributes are the basic metadata for subsequent isolation and control.
[0028] 2. Storage and Indexing: Based on the type and attributes of knowledge assets, store them on appropriate storage media and establish a joint index based on multi-dimensional attributes to support efficient strategy retrieval and knowledge discovery.
[0029] 3. Access Interface Encapsulation: Provides a unified knowledge access API. All read and write operations on knowledge assets through this API are forcibly routed to the "multi-dimensional knowledge isolation method" for permission verification, ensuring that all access behaviors are conducted within a controlled security boundary.
[0030] 4. Knowledge Lifecycle Linkage: At key nodes in the knowledge lifecycle, such as version updates, copying, sharing, archiving, or destruction, the system automatically triggers and applies corresponding multi-dimensional isolation strategies to ensure that security policies remain consistent and continuous as the knowledge status changes. For example, when the security level of a document is upgraded, the system automatically revokes access permissions for all users who no longer meet the requirements of the new level.
Claims
1. A knowledge isolation method based on organizational structure and user responsibilities, consisting of three core modules: an isolation dimension management center (1), a multi-dimensional knowledge isolation method module (2), and a knowledge production center (3), to achieve secure access control of the internal AI knowledge base and prevent the misuse of knowledge, characterized in that: The isolation dimension management center (1) is connected to the multidimensional knowledge isolation method module (2) through the dimension configuration channel (4) to transmit the isolation dimension strategy of organization, task, identity and level; The multidimensional knowledge isolation method module (2) is connected to the knowledge production center (3) through the isolation execution channel (5) and implements isolation control on knowledge access requests according to the received dimension strategy; The knowledge production center (3) outputs knowledge content that conforms to the isolation strategy to authorized users through the knowledge output channel (6).
2. The isolation dimension management center (1) as described in claim 1, responsible for designing and managing the core dimensions of knowledge isolation, is characterized in that: It includes an organizational framework management unit (7) and a task grouping management unit (8), wherein the organizational framework management unit (7) and the task grouping management unit (8) are directly connected; The organizational framework management unit (7) is used to maintain a long-term isolation dimension based on a stable organizational architecture; The task grouping management unit (8) is used to maintain the penetrating isolation dimension based on temporary and dynamically adjusted tasks; The isolation dimension management center (1) also includes a level management unit (9) and a role and permission management unit (10). The level management unit (9) is directly connected to the role and permission management unit (10) and is connected to the multidimensional knowledge isolation module (2) through the dimension configuration channel (4).
3. The multi-dimensional knowledge isolation method module (2) as described in claim 1, responsible for executing knowledge access isolation based on multiple dimensions, characterized in that: It includes an organization-based isolation method unit (11), a task-based isolation method unit (12), an identity-based isolation method unit (13), and a level-based isolation method unit (14). The organization-based isolation method unit (11), the task-based isolation method unit (12), the identity-based isolation method unit (13), and the level-based isolation method unit (14) are set up in parallel and connected to the knowledge production center (3) through the isolation execution channel (5).
4. The knowledge production center (3) as described in claim 1, responsible for the production and output of knowledge under the control of an isolation strategy, characterized in that: It includes a knowledge storage unit (15) and an access control unit (16), wherein the knowledge storage unit (15) and the access control unit (16) are directly connected; The access control unit (16) outputs knowledge content to the external user interface through the knowledge output channel (6).
5. The organizational framework unit (7) as described in claim 2, responsible for maintaining a stable organizational structure isolation dimension, characterized in that: The organization configuration information is received through the dimension configuration channel (4), and the organization isolation strategy is output to the multidimensional knowledge isolation method module (2).
6. The task grouping unit (8) as described in claim 2, responsible for maintaining the dynamic task grouping isolation dimension, characterized in that: The task grouping dynamic adjustment information is received through the dimension configuration channel (4), and the task isolation strategy is output to the multidimensional knowledge isolation method module (2).
7. The isolation dimension management center (1) as described in claim 2 further includes a level management unit (9) and a role and permission unit (10), wherein the level management unit (9) and the role and permission unit (10) are directly connected; The level management unit (9) outputs the level isolation strategy to the multidimensional knowledge isolation method module (2) through the dimension configuration channel (4); The role permission unit (10) outputs the identity (role) isolation strategy to the multidimensional knowledge isolation method module (2) through the dimension configuration channel (4).
8. The organization-based isolation method unit (11) as described in claim 3, responsible for implementing knowledge isolation according to the organizational structure, characterized in that: Access requests are received through the isolation execution channel (5), and the organization determines whether to allow access to the knowledge production center (3) based on its isolation policy.
9. The task-based isolation method unit (12) as described in claim 3, responsible for implementing knowledge isolation based on task grouping, characterized in that: The access request is received through the isolated execution channel (5), and the access to the knowledge production center (3) is determined according to the task isolation policy.
10. The identity-based isolation method unit (13) as described in claim 3, responsible for implementing knowledge isolation based on user role permissions, characterized in that: Access requests are received through the isolated execution channel (5), and the access to the knowledge production center (3) is determined based on the identity (role) isolation policy.